Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpbb HIGH 8.1
CVE-2026-29199

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the ser…

Fix: 3.3.16+
Fix from $1,950 2026-05-04
Phpbb HIGH 8.8
CVE-2025-70810

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the aut…

No fix yet
Fix from $1,950 2026-04-09
Phpbb MEDIUM 6.1
CVE-2023-5917

A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/in…

Fix: 3.3.11+
Fix from $1,600 2023-11-02
Phpbb MEDIUM 5.8
CVE-2020-8226

A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.

Fix: 3.2.10 / 3.3.1+
Fix from $1,600 2020-08-17
Phpbb HIGH 7.5
CVE-2019-16108

phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

Patch available
Fix from $1,950 2020-03-20
Phpbb MEDIUM 6.5
CVE-2020-5502

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

Mitigation only
Fix from $1,600 2020-01-15
Phpbb MEDIUM 6.5
CVE-2019-13376

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token…

No fix yet
Fix from $1,600 2019-09-27
Phpbb MEDIUM 5.8
CVE-2019-11767

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host thr…

Fix: 3.2.6+
Fix from $1,600 2019-05-05
Phpbb HIGH 7.5
CVE-2019-9826

The fulltext search component in phpBB before 3.2.6 allows Denial of Service.

Fix: after 3.2.5
Fix from $1,950 2019-05-02
Phpbb HIGH 7.5
CVE-2017-1000419

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal …

No fix yet
Fix from $1,950 2018-01-02
Phpbb MEDIUM 6.1
CVE-2015-3880

Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web…

Fix: after 3.0.14
Fix from $1,600 2017-09-19
Phpbb MEDIUM 6.8
CVE-2015-1432

The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote a…

Fix: after 3.0.12
Fix from $1,600 2015-02-10
Phpbb HIGH 7.5
CVE-2010-1630

Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstan…

Fix: after 3.0.4
Fix from $1,950 2010-05-19
Phpbb MEDIUM 6.8
CVE-2008-7143

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to …

Mitigation only
Fix from $1,600 2009-09-01
Phpbb MEDIUM 5.0
CVE-2008-6507

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password …

No fix yet
Fix from $1,600 2009-03-23
Phpbb MEDIUM 5.0
CVE-2008-6506

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknow…

Fix: after 3.0.3
Fix from $1,600 2009-03-23
Tag Board HIGH 7.5
CVE-2008-6314

SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL comma…

Fix: after 4.0
Fix from $1,950 2009-02-27
Phpbb MEDIUM 5.0
CVE-2008-4125

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially s…

Mitigation only
Fix from $1,600 2008-09-18
Phpbb HIGH 10.0
CVE-2008-3224

Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within logi…

Fix: after 3.0.1
Fix from $1,950 2008-07-18
Phpbb HIGH 10.0
CVE-2008-1766

Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."

Fix: after 3.0.0
Fix from $1,950 2008-04-12
Module Xs HIGH 7.5
CVE-2008-1512

Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to includ…

No fix yet
Fix from $1,950 2008-03-25
123 Flash Chat Module MEDIUM 6.8
CVE-2008-1171

Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a …

Mitigation only
Fix from $1,600 2008-03-05
Garage HIGH 7.5
CVE-2007-6223

SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id param…

No fix yet
Fix from $1,950 2007-12-04
Phpbb Plus MEDIUM 6.8
CVE-2007-5100

Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a before 20070922, when register_globals is enabled, allow remote atta…

Fix: after 1.53a
Fix from $1,600 2007-09-26
Phpbb HIGH 7.5
CVE-2007-4653

SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary…

Fix: after 2.0.22
Fix from $1,950 2007-09-04
Supanav HIGH 9.3
CVE-2007-3935

PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2007-07-21
Ip Tracking MEDIUM 6.5
CVE-2007-2858

SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execu…

Mitigation only
Fix from $1,600 2007-05-24
Mutant HIGH 7.5
CVE-2007-1961

PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,950 2007-04-11
Dimension HIGH 10.0
CVE-2006-7174

PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP c…

Mitigation only
Fix from $1,950 2007-03-21
Phpbb HIGH 7.5
CVE-2006-7168EPSS 7%

PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2007-03-20